show logging
Displays the syslog messages in the device
local buffer.
Modes
User EXEC mode
The
show logging command displays the following information.
Examples
The following is a sample output from the show logging
command.
device# show logging
Syslog logging: enabled ( 0 messages dropped, 0 flushes, 0 overruns)
Buffer logging: level ACDMEINW, 5 messages logged
level code: A=alert C=critical D=debugging M=emergency E=error
I=informational N=notification W=warning
Static Log Buffer:
Mar 07 15:14:42:I:System: Stack unit 1 Power supply 2 is up
Dynamic Log Buffer (4000 lines):
Mar 07 15:18:48:I:conf_archive:Succeeded to full revert
Mar 07 15:18:47:I:conf_archive:Revert due to revert timeout
Mar 07 15:17:40:A:Startup Config Parsing Returned Error. Please verify the system configuration.
Mar 07 15:14:48:I:System: Interface ethernet mgmt1, state up
Mar 07 15:14:42:I:System: Stack unit 1 Power supply 2 is up
ICX7850-48FS Router#
The following example shows the ICX syslog messages
generated when the OS configuration mode is entered for password recovery by
executing commands such as
reset_login,
erase-startup-config, copy, and
reboot. These log messages are generated with a severity
level of “Warning” and are also displayed on the management platform for this device
(specifically, the Events page of the RUCKUS One or SmartZone web UI). Syslog
messages are not generated when an administrator enters the OS mode of a standby or
member unit in a stacking
setup.device(config)# show logging Sep 11 17:10:56:W:os_shell: Security: User executed erase_startup_config command in OS mode. Sep 11 17:10:46:W:os_shell: Security: User entered into OS mode. Sep 11 17:10:24:W:os_shell: Security: User executed reset_login command in OS mode. Sep 11 17:10:05:W:os_shell: Security: User entered into OS mode. Sep 11 17:10:00:I:Security: console login by super to PRIVILEGED EXEC mode Sep 11 17:10:00:I:Security: console login by super to USER EXEC mode
The following example shows syslog messages with
authentication attempts and failures on the switch. Log messages for login failures
across TELNET, SSH, and Console sessions has now been changed from "Informational"
to a severity level of "Warning" and are also displayed on the device's management
platform (specifically, the Events page of the RUCKUS One or SmartZone web
UI).
device(config)# show logging Sep 11 05:48:35:W:login: TELNET access by user super rejected for incorrect login Sep 11 05:47:09:I:Security: console login by super to PRIVILEGED EXEC mode Sep 11 05:46:45:I:Security: console login by super to USER EXEC mode Sep 11 05:44:51:W:login: Console access by user super failed
device(config)# show logging Sep 11 05:48:26:W:sshd-session: SSH access by user super from src IP 10.246.201.89 rejected, 1 attempt(s) Sep 11 05:48:22:W:sshd-session: Failed publickey SSH access by user super from 10.246.201.89
The following sample shows
output from the
show logging command when the RFC 5424 format has
been
enabled.device(config)# show logging
Syslog logging: enabled (RFC: 5424, 0 messages dropped, 1 flushes, 0 overruns)
Buffer logging: level ACDMEINW, 12 messages logged
level code: A=alert C=critical D=debugging M=emergency E=error
I=informational N=notification W=warning
Dynamic Log Buffer (4000 lines):
2023-10-31T19:11:45Z:I: ruckuswireless.com device ICX7850_Router - General [meta sequenceId=12] BOM MGMT Agent: Failed to connect to network controller at 10.177.86.160 Error:
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=11] BOM COPY COMPLETED
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=10] BOM Security: startup-config was changed
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=9] BOM COPY_CONFIGURATION_TO_FLASH
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - General [meta sequenceId=8] BOM Security: startup-config was changed by super from CONSOLE
.
.
.
History
| Release version | Command history |
|---|---|
| 09.0.10 | The output of this command was modified to include details for Configuration Archive and Replace configurations. |